StackRadar

CVE-2026-0636

Medium

Advisory

Published 15 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
124
of 17,781 indexed, latest versions
Container images
131
deployed by those charts
Fix available
2 of 3
affected packages

Bouncy Castle has an LDAP injection

Carried by container images the latest versions of 124 of 17,781 indexed charts deploy, on 131 images.

Affected packageAffected versionsFixed inImages
bcprov-jdk18onmaven1.74, 1.75, 1.76, 1.77+9 more1.84124
bcprov-jdk15to18maven1.74, 1.75, 1.76, 1.78+4 more1.8415
bouncycastledeb1.61-1no fix listed1
OSV records
GHSA-c3fc-8qff-9hwxUBUNTU-CVE-2026-0636

Charts affected

124 by stars
ChartLatestAffected imagesRadar Score
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
bcprov-jdk18on@1.81
1.84

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
bcprov-jdk15to18@1.75
bcprov-jdk18on@1.78
1.84
1.84

Open the chart page →

1,753
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,097
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bcprov-jdk18on@1.77
1.84

Open the chart page →

5,269
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,284
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,465
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
bcprov-jdk18on@1.76
1.84

Open the chart page →

4,203
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,590
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
bcprov-jdk18on@1.81
1.84

Open the chart page →

1,690
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
bcprov-jdk15to18@1.75
1.84

Open the chart page →

4,946
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
bcprov-jdk18on@1.80
1.84

Open the chart page →

3,153
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
bcprov-jdk18on@1.79
1.84

Open the chart page →

1,827
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

5,063
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

4,674
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
bcprov-jdk18on@1.78
1.84

Open the chart page →

2,144
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
bcprov-jdk18on@1.80
1.84

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
bcprov-jdk18on@1.80
1.84

Open the chart page →

1,689
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

45,239
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.82
1.84
1.84

Open the chart page →

5,484
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
bcprov-jdk18on@1.79
1.84

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
bcprov-jdk18on@1.82
1.84

Open the chart page →

7,624
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.78.1
1.84
1.84

Open the chart page →

9,381
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

1,159

Container images carrying it

131 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
guacamole/guacamole:1.6.0f344085e618b
bcprov-jdk15to18@1.80
1.84
3
jacobalberty/unifi:v10.0.162896c0ab82d33
bcprov-jdk18on@1.78.1
1.84
3
airbyte/workload-launcher:2.2.0119be7bfb719
bcprov-jdk18on@1.79
1.84
2
apache/druid:37.0.00116fb802786
bcprov-jdk18on@1.82
1.84
2
apache/nifi-registry:1.26.07cdfd8deec92
bcprov-jdk18on@1.78.1
1.84
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
bcprov-jdk18on@1.78.1
1.84
2
hazelcast/management-center:5.5.2991ddb27c251
bcprov-jdk18on@1.78.1
1.84
2
inaccel/coral:2.18c53744ed70b
bcprov-jdk18on@1.77
1.84
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
bcprov-jdk18on@1.82
1.84
2
library/elasticsearch:8.19.1289729a95066a
bcprov-jdk18on@1.79
1.84
2
nacos/nacos-server:latest1c191c30c8cd
bcprov-jdk18on@1.79
1.84
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.78.1
1.84
1.84
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
bcprov-jdk18on@1.82
1.84
2
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly7752874e71d8
bcprov-jdk18on@1.79
1.84
2
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly900e2b88bd08
bcprov-jdk18on@1.79
1.84
2
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly2a797804f08c
bcprov-jdk18on@1.79
1.84
2
ghcr.io/janssenproject/jans/scim:0.0.0-nightly096b8bcbbe45
bcprov-jdk18on@1.79
1.84
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
bcprov-jdk18on@1.78.1
1.84
2
1dev/server:11.9.0cd5b12fe5471
bcprov-jdk18on@1.74
1.84
1
2martens/configserver:latestbf1cdb80239d
bcprov-jdk18on@1.78
1.84
1
2martens/timetable:latestbd1ba6ab84c9
bcprov-jdk18on@1.80
1.84
1
2martens/wahlrecht:latestba2c3040dab0
bcprov-jdk18on@1.80
1.84
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
bcprov-jdk18on@1.83
1.84
1
adityaprasadpathak/myapp:3.07e3b9777362c
bcprov-jdk18on@1.78.1
1.84
1
apache/activemq-artemis:2.37.0bae523439ee3
bcprov-jdk18on@1.78.1
1.84
1
apache/druid:29.0.10cef139b6bf1
bcprov-jdk18on@1.76
1.84
1
apache/nifi-registry:1.27.063b8e3e40742
bcprov-jdk18on@1.78.1
1.84
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
bcprov-jdk18on@1.75
1.84
1
apachepulsar/pulsar:3.0.79c9947de139d
bcprov-jdk18on@1.78.1
1.84
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
bcprov-jdk18on@1.76
1.84
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
bcprov-jdk18on@1.76
1.84
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
bcprov-jdk18on@1.78.1
1.84
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
bcprov-jdk18on@1.77
1.84
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
bcprov-jdk18on@1.81
1.84
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.78
1.84
1.84
1
bluerange/bluerange:26.1.307c8f73b55df
bcprov-jdk18on@1.79
1.84
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
bouncycastle@1.61-1
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
bcprov-jdk18on@1.77
1.84
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
bcprov-jdk18on@1.78
1.84
1
conductoross/conductor:3.31.09fba127693e6
bcprov-jdk18on@1.78.1
1.84
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bcprov-jdk18on@1.77
1.84
1
consensys/teku:25.4.1bf6ecd2ea716
bcprov-jdk18on@1.80
1.84
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
bcprov-jdk18on@1.77
1.84
1
flowable/flowable-rest:7.1.0b7ae287502cd
bcprov-jdk18on@1.77
1.84
1
folioci/mod-data-export:latest0cc86bf09755
bcprov-jdk18on@1.81
1.84
1
folioci/mod-data-export-worker:latest1ad1811c9b37
bcprov-jdk18on@1.81
1.84
1
folioci/mod-entities-links:latest3e2412815c0f
bcprov-jdk18on@1.81
1.84
1
folioci/mod-search:latest44d7ee9acdf6
bcprov-jdk18on@1.81
1.84
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
bcprov-jdk18on@1.79
1.84
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
bcprov-jdk18on@1.81.1
1.84
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.